var addr sto mov addr,esp //ESP定律 bphws addr,"r" run bphwc addr //清除硬件访问断点 sto //单步一下来到oep mov addr,eip and addr, 0f00000 add addr,3900 bp addr run bc addr MSG "You get back it!" add addr,47 bp addr run bc addr gpa "ExitProcess","kernel32.dll" mov eax,$RESULT asm eip, "push 0" asm eip+5, "call eax" run